CVE-2024-41752

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 18, 2024
Updated: Jan 10, 2025
CWE ID 79
CWE ID 80

Summary

CVE-2024-41752 is a vulnerability affecting IBM Cognos Analytics versions 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3. This issue allows remote attackers to inject malicious HTML code into the system. When a user views the affected page, the injected code gets executed in their web browser, running in the hosting site's security context. This poses a significant risk as it could lead to various attacks, including phishing, data theft, and privilege escalation. Users are strongly advised to update their IBM Cognos Analytics installations to the latest, secure versions to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • IBM Cognos Analytics

Affected Vendors

  • IBM Corporation